1200KM / simulation
T1137.005 Outlook Rules — Attack Simulation
Adversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system. Outlook rules allow a user to define automated behavior to manage email messages. A benign rule might, for example, automatically move an email to a particular folder in Outlook if it contains specific words from a specific sender. Malicious Outlook rules can be created that can trigger code execution when an adversary sends a specifically crafted email…
Technique description
Adversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system. Outlook rules allow a user to define automated behavior to manage email messages. A benign rule might, for example, automatically move an email to a particular folder in Outlook if it contains specific words from a specific sender. Malicious Outlook rules can be created that can trigger code execution when an adversary sends a specifically crafted email…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Outlook Rules - Enumerate Existing Rules via PowerShell COM Object
Procedure 5ff5249a-5807-480e-ab52-c430497a8a25; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Outlook Rule - Auto-Forward Emails to External Address via COM Object
Procedure b0bd3d76-a57c-4699-83f4-8cd798dd09bd; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Outlook Rule - Sender Address Trigger with DeletePermanently Action via COM Object
Procedure bddfd8d4-7687-4971-b611-50a537ab3ab4; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Outlook Rule - Create Rule with Obfuscated Blank Name (MAPI Evasion)
Procedure cb814cf8-24f2-41dc-a1cd-1c2073276d4a; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Outlook Rule - Subject Trigger with DeletePermanently Action via COM Object
Procedure ffadc988-b682-4a68-bd7e-4803666be637; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.